Attackers stole customer names, emails, phone numbers, and addresses from BigCommerce stores by hijacking a third-party app's access key.
BigCommerce confirmed that credentials belonging to Ribon and Ribon 1.5, a storefront app made by "Be A Part Of," a Fastr company, were compromised between September 13 and 17, 2026. Attackers used the stolen key to inject malicious scripts and pull customer data from merchant storefronts before BigCommerce revoked access and uninstalled the app. Online spirits retailer Master of Malt, one of the affected merchants, notified customers that their names, emails, phone numbers, and addresses were exposed - though passwords and payment details, stored separately, were untouched. Master of Malt says the app was installed on hundreds of BigCommerce stores, and multiple retailers are now notifying their own customers.
BigCommerce's own description - "a small number of merchant storefronts" - undercuts what Master of Malt is telling customers directly, and the discrepancy matters for anyone trying to gauge their exposure. This is a supply-chain breach: the platform itself wasn't hacked, a single third-party integration was, and that one weak link fanned out to every store that trusted it. Ecommerce platforms increasingly run on stacks of bolt-on apps, and this incident is a reminder that a storefront is only as secure as its least-scrutinized plugin.
Law firm Emery Reddy is already fielding potential claims and warning of follow-up phishing attempts - the kind of second-wave fallout that tends to outlast the headlines about the breach itself.